Release date:
2025-12-08 15:17:35 UTC
Description:
* SECURITY UPDATE: Marvin Attack vulnerability in Node.js
– debian/patches/CVE-2023-46809.patch: fixes a timing‑side‑channel
flaw in the RSA PKCS#1 v1.5 decryption logic, preventing a Marvin‑style
padding‑oracle attack that could allow recovery of sensitive data.
– CVE-2023-46809
Updated packages:
-
alt-nodejs14-docs_14.21.3-11_amd64.deb
sha:29554d50de035a81fb3dbcf3a9b3787ca6b0d30f
-
alt-nodejs14-nodejs_14.21.3-11_amd64.deb
sha:cc8b809d2725842e8edb1c9b16815633ca574736
-
alt-nodejs14-nodejs-devel_14.21.3-11_amd64.deb
sha:29c6a3f95e39d50879603c7ae222cbefbb340c4f
-
alt-nodejs14-npm_6.14.18-14.21.3.11_amd64.deb
sha:73b2278b11a904ccbc99c268db9c7a8f1669c6b9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.